Analyst Harrison Berger in the publication Responsible Statecraft (Quincy Institute) on September 21, 2026, describes how AI companies are already embedded in the U.S. security apparatus, not just that they 'could become dangerous' in the future. According to the data he provided, Claude is used in the Palantir Maven system to prioritize strike targets against Iran, Anthropic is helping the NSA with the Mythos model for offensive cyber operations, and OpenAI is working under contract with U.S. Cyber Command. New fact: The FBI is seeking AI vendors on the SAM.gov platform for the Threat Screening Center (TSC), which maintains the federal watchlist, and among the system requirements, predictive modeling is stated. This is currently a request for information, not a deployed system, but the contours of the 'pre-crime' AI market are already being formed by active government procurement.

image
image

What happened

On September 21, 2026, analyst Harrison Berger published an article titled 'Police hugging AI so tight, soon we'll all be pre-crime suspects' in the publication Responsible Statecraft (Quincy Institute). Its thesis: the question is not whether AI companies can become dangerous in the future, but that they are already embedded in the U.S. security apparatus. Berger relies on investigations by Jack Pulson (Plain Text publication), Financial Times, WSJ, and NYT. According to this summary, Anthropic as early as November 2023 discussed the implementation of LLMs in the work of intelligence agencies with the CIA and the Australian National Intelligence Directorate at a closed workshop. Claude is used in the Palantir Maven system to prioritize strike targets against Iran, Anthropic, despite its 'supply-chain risk' status, is helping the NSA with the Mythos model for offensive cyber operations, and on October 16, 2025, OpenAI signed a one-year contract for $3.5 million with U.S. Cyber Command. Key new fact: On March 27, 2026, the FBI posted a request for information (RFI) on SAM.gov for the Threat Screening Center (TSC, formerly the Terrorist Screening Center), where among six requirements, predictive modeling is listed — the application used the phrase 'predictive modeling using enhanced data with traceable lineage'.

Context

The Threat Screening Center is the former Terrorist Screening Center, a federal structure that maintains the official watchlist. Publications Reason and Military.com, which wrote about this application in July 2026, note that the center has already been renamed and expanded its mission beyond terrorism, and GAO (Government Accountability Office) data confirms the transfer of its data to state police. In other words, the infrastructure that is planned to be supplemented with predictive modeling is not a paper project, but an operating system. The mechanics of procurement here are more important than loud words: an RFI is a request for information from which the search for vendors begins, not a contract and not a deployed system. The template for such procurement has already been set by active agreements: ICE concluded a $30 million contract with Palantir for ImmigrationOS, Zignal Labs received $5.7 million for social media monitoring, and DHS, according to FedScoop data, plans to spend over $100 million on AI surveillance.

Why this matters for the industry

For the industry, this is a shift in the role of vendors: government procurement turns LLM companies from providers of 'assistants' into infrastructure for targeting strikes and surveillance, and the pre-crime AI market is already being formed at the procurement stage — requirements for vendors are publicly fixed in applications like the FBI's RFI, not in press releases. Government procurement becomes an open source of product specifications: from it, you can see which workflows the customer is actually buying — in this case, data traceability (lineage) and predictive screening across departmental databases. For engineers and startups, the conclusion is that in high-stakes government contracts, it is not the models that decide, but data and control: closed deployment loops, audit logs, data provenance, so demand is shifting towards high-assurance MLOps, and a realistic move for a young team is positioning around data quality and traceability and responding to such applications. For Anthropic, this is also a direct reputational conflict between the 'safe AI' brand and participation in the Maven strike loop and NSA offensive cyber operations.

Why this matters for users

The main thing for the reader is not to confuse a request for information with a working tool: the FBI is currently only looking for vendors, there are no signed contracts under this RFI, and headlines about a ready-made 'pre-crime' tool are getting ahead of themselves. At the same time, the watchlist itself is an operating infrastructure, and if predictive modeling becomes part of the screening, the risk for a person is an erroneous inclusion in the list based on a forecast, and without public error metrics, such a decision will be practically impossible to challenge. The picture can be checked independently: Harrison Berger's article is open on responsiblestatecraft.org, and the FBI application should be found by number on SAM.gov and the wording about predictive modeling should be read with your own eyes.

What is still unknown / limitations

The RFI has no budget, acceptance criteria, or model validation requirements: neither a specific model nor its type (LLM or classic ML), nor error rate, nor false positive rate is named, so it is impossible to compare solutions or reject unsuitable ones based on this application. It is unknown whether the RFI will transition to an RFP and contract or be quietly closed. The assessment that watchlist scoring is a task with an extremely low base rate, where false positives dominate, is a methodological interpretation, not a fact from sources. The facts of the integrations themselves (Claude in Maven, Mythos at NSA, OpenAI's contract with U.S. Cyber Command) rely on secondary investigations, not vendor disclosures, so the performance characteristics of these systems cannot be verified.

Sources

Author

Look at AI, editorial team